Open Thoughts https://judah.freedomland.xyz// en Thu, 21 Dec 2023 00:00:00 -0500 Thu, 21 Dec 2023 20:05:56 -0500 weblorg 0.1.0 (https://emacs.love/weblorg) Judah Sotomayor https://judah.freedomland.xyz//media/img/8bitme.png Blog Author https://judah.freedomland.xyz// RSS Feed https://judah.freedomland.xyz//posts/rss-feed.html author@mail.com (Blog Author) https://judah.freedomland.xyz//posts/rss-feed.html Thu, 21 Dec 2023 00:00:00 -0500 Rather than an email-based subscription service, I'll be using RSS. It's an amazing subscription mechanism used by a lot of blogs and podcasts. All you need to subscribe is an RSS client, which you can pass my link.

]]>
My SSH Key https://judah.freedomland.xyz//posts/my-ssh-key.html author@mail.com (Blog Author) https://judah.freedomland.xyz//posts/my-ssh-key.html Wed, 08 Nov 2023 00:00:00 -0500 In the interest of integrity, here is my public ssh key. This is the key I use to sign all of my commits. If any project purports to be from me, and is not signed by this key, there is a strong chance it is disingenuous.

Key:


ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII0YkBVeeBhoCm/+6mCteO7Ikv528ZDmg/tYtWc6O1qP

Fingerprint:


SHA256:9Dq4ppxhfAjbX+7HLXEt+ROMiIojI6kqQgUyFUJb9lI

Directions

If you're cloning a project off a major git platform, you can check that the latest commit states "Verified" or "Signed". Then you can check that my key fingerprint matches with the one above.

If you've gotten ahold of source code some other way, run git verify-commit HEAD to ensure that the latest commit has been signed.

Example

git verify-commit HEAD

Good "git" signature for development@freedomland.xyz with ED25519 key SHA256:9Dq4ppxhfAjbX+7HLXEt+ROMiIojI6kqQgUyFUJb9lI

Website repo

This link directs to my website's source code. You can check that the latest commits are signed with my key.

]]>
QubesOS Signing Key https://judah.freedomland.xyz//posts/qubesos-signing-key.html author@mail.com (Blog Author) https://judah.freedomland.xyz//posts/qubesos-signing-key.html

Double check your keys!

Do not blindly trust me. Find another website or another source for the key.

Find a photograph or other item that is difficult to forge.

This is the signature for the Qubes master signing key. I provide it here as another copy of a currently known-good key. The QMSK is the root of trust for all QubesOS development. Qubes release keys and developer keys are all signed with the QMSK.

Please see the Qubes website for more information.


427F 11FD 0FAA 4B08 0123
F0IC DDFA 1A3E 3687 9494

]]>